CVE-2023-38486
06.09.2023, 18:15
A vulnerability in the secure boot implementation on affectedAruba 9200 and 9000 Series Controllers and Gateways allowsan attacker to bypass security controls which would normallyprohibit unsigned kernel images from executing. An attackercan use this vulnerability to execute arbitrary runtimeoperating systems, including unverified and unsigned OSimages.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | arubaos | 8.6.0.22 < 𝑥 < 8.6.0.22 |
arubanetworks | arubaos | 8.10.0.7 < 𝑥 < 8.10.0.7 |
arubanetworks | arubaos | 8.11.1.1 < 𝑥 < 8.11.1.1 |
arubanetworks | arubaos | 10.4.0.2 < 𝑥 < 10.4.0.2 |
arubanetworks | arubaos | 8.6.0.0 ≤ 𝑥 < 8.6.0.22 |
arubanetworks | arubaos | 8.10.0.0 ≤ 𝑥 < 8.10.0.7 |
arubanetworks | arubaos | 8.11.0.0 ≤ 𝑥 < 8.11.1.1 |
arubanetworks | arubaos | 10.4.0.0 ≤ 𝑥 < 10.4.0.2 |
𝑥
= Vulnerable software versions